North Carolina's product-security and cyber-resilience posture, for a private-sector operator, rests on one enacted state statute with a narrow scope: the Identity Theft Protection Act's destruction-of-records duty, N.C. Gen. Stat. section 75-64 (Chapter 75, Article 2A, added by S.L. 2005-414, s. 1, effective December 1, 2005), which requires any business that conducts business in North Carolina, or that maintains or otherwise possesses the personal information of a North Carolina resident, to take reasonable measures, described in the statute as burning, pulverizing, or shredding paper records and destroying or erasing electronic and other nonpaper media, to protect against unauthorized access to or use of personal information in connection with or after its disposal.
The duty reaches only the disposal phase; it does not extend, the way New York's SHIELD Act safeguards duty or Massachusetts's 201 CMR 17.00 do, to a general written information-security-program requirement for personal information while it remains in active use, and no such general requirement was located in North Carolina law. No enacted North Carolina statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market.
North Carolina has no general private-sector duty to report an exploited vulnerability or a security incident to an authority: the state's Ransomware Act, N.C. Gen. Stat. section 143-800 (Chapter 143, Article 84, added by S.L. 2021-180, s. 38.13(a)), bars a state agency or local government entity from paying or communicating with a ransomware attacker and requires either to consult the Department of Information Technology on a ransom request, but both bound terms are defined to reach only government bodies, so this belongs with the jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.
The state's one sector-specific security regime, N.C. Gen. Stat. sections 58-39-130 to 58-39-165 (Chapter 58, Article 39, Part 3, "Customer Information Safeguards," added by S.L. 2003-262, s. 4, effective April 1, 2005), implements the federal Gramm-Leach-Bliley Act's safeguards requirements for the insurance sector, requiring each "licensee," an insurance producer, insurer, multiple employer welfare arrangement, HMO, or Chapter 58 service corporation, to implement a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to its size and complexity and the nature and scope of its activities.
North Carolina has not separately adopted the newer NAIC Insurance Data Security Model Law: a full-text search of Chapter 58's own section index for "cybersecurity" and "data security" returned nothing outside this 2003 Gramm-Leach-Bliley Act (GLBA)-based Part. Because "licensee" is a role the LexLint activity vocabulary cannot yet express, no instrument for this duty is filed here (#6740), and it is recorded in this summary so a reader knows it exists.
G.S. 75-64 is enforced as a deemed violation of the state's general unfair-or-deceptive-trade-practices statute, G.S. 75-1.1: a person injured by a violation may bring a civil action under G.S. 75-16 for treble the damages found, with treble damages for a nonmanagerial employee's own acts or omissions available only where the business was negligent in training, supervising, or monitoring that employee, and the Attorney General may separately sue to enjoin a violation.
No capped or per-violation civil-penalty figure is recorded for this instrument because the statutory remedy is trebled actual damages rather than a stated amount, and no published enforcement record specific to this duty was located.
North Carolina's breach-notification duty, the Identity Theft Protection Act's G.S. 75-65, is already this jurisdiction's privacy row rather than repeated here, and a narrower, adjacent duty at G.S. 75-62(c), requiring a business handling social security numbers to make reasonable efforts, including systems testing, to ensure that Article's SSN-protection requirements are implemented, also stays with that privacy row rather than being filed separately here.